Privacy Policy
Draft for legal review. Replace every [bracketed] item and have a Philippine data-privacy lawyer review this before launch.
- Your prayer intentions, journal and notes are private unless you share them with a group.
- Your examination of conscience never leaves your phone.
- The apps you choose for Prayer Lock, and how you use them, stay on your phone. We never receive that list.
- No ads, ever. We don't sell or rent your data, and we don't use advertising trackers.
- You can download or delete your data at any time.
1. Who we are
Gracio ("we", "us") is operated by [Company legal name], [registered address], Philippines. We are the personal information controller for the Gracio apps on iOS and Android and for gracio.app. Our Data Protection Officer can be reached at privacy@gracio.app.
This policy follows the Data Privacy Act of 2012 (Republic Act No. 10173), its Implementing Rules and Regulations, and issuances of the National Privacy Commission (NPC). Where they apply, we also respect the EU/UK GDPR and US state privacy laws for users abroad.
2. What we collect and why
| Information | Examples | Why we use it |
|---|---|---|
| Account | Name (optional), mobile number or email, Sign in with Apple/Google identifier, profile photo (optional), language, time zone | Create your account, sign you in, sync across devices, show the right local times |
| Prayer information (sensitive) | Routines, prayer intentions, answered-prayer notes, Bible highlights, bookmarks and notes, novena and reading-plan progress, prayer sessions (date, length) | Run the features you use and show your own history. Religious information is sensitive personal information under the Data Privacy Act; we process it only with your consent |
| Group content | Messages, 🙏 reactions, photos, PDFs, songs, events, RSVPs, live prayer participation | Deliver group features to the members of that group |
| Prayer Lock | Your schedule, session length, number of apps locked, lock and unlock events | Back up your settings and show your prayer history. The list of apps and your app-usage data are processed only on your device (Android Usage Access / iOS Screen Time) and never sent to us |
| Device & diagnostics | Push token, app version, OS version, crash reports, pseudonymous feature-usage events | Send notifications you asked for, fix bugs, improve the app. You can turn analytics off in Me → Settings → Privacy |
| Purchases | Subscription product, status, trial and renewal dates | Give you Gracio Plus. Payment details (card, GCash, Maya) are handled by Apple or Google; we never see them |
| Support | Emails and attachments you send us | Answer you |
What we don't collect: contacts, precise location, advertising identifiers, or the content of other apps. An event's address is only what an organizer types in.
The examination of conscience is stored only on your device, is cleared after 24 hours or when you tap "Clear all", and is excluded from backups, analytics and crash reports.
3. Legal bases
- Consent: for sensitive personal information (prayer information), optional analytics and notifications. You can withdraw consent at any time in the app.
- Contract: to provide the service and subscriptions you signed up for.
- Legitimate interests: security, preventing abuse, and improving Gracio, balanced against your rights.
- Legal obligation: responding to lawful requests and keeping required records.
4. Who we share it with
We don't sell or rent personal information. We share it only with:
- Members of groups you join: only what you post or share there, plus your name and photo.
- Service providers under data-processing agreements: Supabase (database, file storage; hosted in [region, e.g. Singapore]), Expo (push notifications), Apple and Google (sign-in, push delivery, payments), RevenueCat (subscription status), Sentry (crash reports), PostHog (pseudonymous analytics), [SMS provider] (one-time login codes), and our email provider.
- Authorities: when required by law, or to protect someone's life or safety, including reports of child sexual abuse or exploitation (see our Child Safety Standards).
Some providers process data outside the Philippines (for example in Singapore, the United States or the EU). We use contractual safeguards so your information keeps the protection the Data Privacy Act requires.
5. How long we keep it
- Account and prayer information: while your account is active. When you delete your account, it is erased within 30 days, and from backups within a further 30 days.
- Group messages and files you posted are deleted with your account. Events you created remain for the group with your name removed.
- Crash and analytics data: up to 12 months.
- Purchase records: as long as tax and accounting law requires.
6. Your rights
Under the Data Privacy Act you have the right to be informed, to access, to object, to erasure or blocking, to rectification, to data portability, to damages, and to file a complaint with the National Privacy Commission. In the app:
- Me → Settings → Privacy → Download my data gives you a copy (JSON).
- Me → Help & safety → Delete account, or follow the steps on gracio.app/delete-account.
- For anything else, email privacy@gracio.app. We reply within 15 working days.
7. Children
You must be at least 13 to create a Gracio account (or older if your country requires it). Children can pray along on a parent's device, for example during a family Rosary. If you believe a child under 13 has an account, contact us and we will delete it.
8. Security
Data is encrypted in transit (TLS) and at rest. Access is limited by row-level security, so group content is readable only by its members. Staff access is restricted and logged. If a breach affects your information, we will notify you and the NPC as the law requires.
9. Changes
If we change this policy in a meaningful way, we'll tell you in the app before the change takes effect.
10. Contact
Data Protection Officer, [Company legal name], [address] · privacy@gracio.app